5 ms·
Hello, Anything being worked on the IO performance side of Defender? I’m still using a paid third party AV for this sole reason. The impact is so huge with NPM
by alibert 5y ago
Hello,
Anything being worked on the IO performance side of Defender? I’m still using a paid third party AV for this sole reason. The impact is so huge with NPM packages as an example…
- bob1029 5y agoIO impact is why I disable it on all my dev machines. Microsoft really needs to make this easier to turn off too. Right now, I have to use an undisclosed privilege escalation hack-around to force things my way.
- tomnipotent 5y agoYou can add folder and extension exclusions to Defender. I do this to the root of my source code folders and it helps immensely.
- jraph 5y agoOn the other hand, isn't node_modules the folder that shouldn't be excluded from antivirus scan?
- sundvor 5y agoPerhaps it's one better suited for periodic scanning? At least from a performance point of view. Perhaps one ought to have live scanning enabled when updating packages, then disabled when not. I look forward to seeing other replies.
- tomnipotent 5y agoThe challenge is that excluded folders/extensions apply to both real-time scanning and manual/periodic scanning. What we really need is the ability to disable real-time scanning on one set of folders/extensions, while still including them with scheduled system-wide scans.
- sundvor 5y agoThanks, that's a great point. It made me think we could probably do this programmatically - perhaps as part of a script to carry out the full scan? Add the folders of interest, scan, then remove when completed. https://docs.microsoft.com/en-us/powershell/module/defender/add-mppreference?view=windowsserver2022-ps https://docs.microsoft.com/en-us/powershell/module/defender/... https://docs.microsoft.com/en-us/powershell/module/defender/remove-mppreference?view=windowsserver2022-ps https://docs.microsoft.com/en-us/powershell/module/defender/... Or, even just run said folders as a custom scan! `Start-MpScan -ScanType CustomScan -ScanPath PATH\TO\FOLDER-FILES`
- ChuckNorris89 5y ago>I’m still using a paid third party AV for this sole reason. Would you mind naming it? AFAIK most third party anti-malware solutions act like rootkits, possibly introducing new attack vectors, or have become basically ad-ware and malware themselves trying yo bait you in various subscriptions.
- alibert 5y agoI’m using Nod32 from Eset for almost a decade now. All AV somehow have to hook into low level system calls so can’t really avoid the kernel driver. Nonetheless, nod32 has been an install and forget AV with no interruption nor bait/nag screen at all. It’s a no bullshit AV and it does well. I supposedly get the same protection as Defender (according to various AV tests review) and most importantly I get the IO performance back.
- ziml77 5y agoThat's also what I'm using and for the same reasons. Defender's protection is fine according to testing, but the IO performance is insanely bad. I wouldn't bother with running ESET's AV if Defender didn't slow heavy disk IO operations to a crawl. And I'm not excluding any development directories because malicious code can come in either as part of the project I just pulled down from github or from pulling in one of its dependencies from a package index.
- varenc 5y ago> All AV somehow have to hook into low level system calls so can’t really avoid the kernel driver. While I don’t doubt this true for Windows, on macOS Apple is phasing out kernel modules with APIs that allow software to hook into those low level calls without actually running in the kernel. For AV vendors there’s the Endpoint Security System Extension: https://developer.apple.com/documentation/endpointsecurity https://developer.apple.com/documentation/endpointsecurity All the AV/endpoint security solutions I’ve seen have switched to this.
- ChuckNorris89 5y ago
- cptskippy 5y agoI've been forced to use a number of products over the years at work from Trend Micro to McAfee. They all need curated exclusion lists and we have to ask developers to put all source controlled files under an excluded path common for all devs. McAfee is by far the worst offender IMO when it comes to file IO. We eventually dropped it in part to it's insistence on locking files in App Data which is a common scratch space for almost every Windows App.
- londons_explore 5y agoto be fair, most malware hides in App Data too... it's a convenient place thats hard to find using windows explorer and guaranteed to be user-writable.
- cptskippy 5y agoYes and McAfee was locking files for tens of seconds while it scanned. Things like Visual Studio and Notepad++ would become unresponsive after a single keystroke.
- hermitdev 5y agoBack when I had to use McAfee on a work PC; I was using WSL 1 for building the projects I was running. Symptom was basically: do a compile, lose most of your RAM until next reboot. Stopping WSL wouldn't reclaim it; nothing showed up in Task Manager, Process Explorer, etc. The RAM was just gone; unusable. Post a bug to WSL, was immediately asked if I had McAfee and if so to disable/uninstall. Problem solved. But, due to insurance reasons, I had to have an AV running, and powers that be decided Defender was sufficient. Never McAfee again. It's been a pile of crap for decades; no signs of it getting better, either.
- londons_explore 5y agoI really don't understand why the IO hit... If you're designing the OS, you can either scan a file when it's written to disk, or when it's read from disk, or sometime inbetween. when you have scanned a given file, you need not rescan it if the file hasn't changed. These facts together mean that it should be really rare that any application needs to be waiting for any scanning - since scanning can happen anytime between a data write and a read of the same data.
- XorNot 5y agoNo way to tell if it's changed if you don't store a hash as metadata. Something like ZFS where hashing is baked into the cost of the FS operation could optimise this.
- londons_explore 5y agoBut if you control the kernel and all the code that runs in the kernel, you know exactly who has written to disk and when. So if nobody wrote that data, then it hasn't changed.
- netcoyote 5y agoThe virus might be discovered after the file it’s contained in is written to disk, which is why you’d need to scan when reading.
- pelorat 5y agoExclude your dev folders and your compiler from being scanned. The only way you'll get malware nowadays is from your web browser.
- alibert 5y agoUnfortunately you can get viruses from rogue npm package. https://www.bleepingcomputer.com/news/microsoft/malicious-npm-packages-used-to-install-njrat-remote-access-trojan/amp/ https://www.bleepingcomputer.com/news/microsoft/malicious-np...